Description
A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to manage organizations can create an invitation for a non-existent email address and then retrieve the secret registration link directly through the application programming interface. By using this link, the administrator can create new user accounts and add them to the organization without having the required user management permissions or access to the invited email account. This allows an administrator to bypass security boundaries and add unauthorized members to an organization.
Published: 2026-07-17
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Keycloak's organization management component allows a delegated administrator who has invitation for a non‑existent e‑mail address. The administrator can then retrieve the programmatic invitation link. With that link the administrator can create new user accounts and add them to the organization, bypassing the required user‑management permissions and the need to access the invited e‑mail account. This effectively lets an administrator add unauthorized members to an organization, breaking the intended security boundaries. This constitutes a CWE‑284 Authorization Bypass using Improper Authorization weakness.

Affected Systems

This vulnerability affects Red Hat Build of Keycloak, Red Hat Single Sign‑On 7, Red Hat Data Grid 8, and Red Hat JBoss Enterprise Application Platform Expansion Pack. The specific affected versions are not listed in the CNA data; any installation that has not yet applied the vendor‑remediated update is vulnerable.

Risk and Exploitability

The CVSS score of 4.9 indicates moderate severity, and the EPSS score of < 1 % indicates a low probability of exploitation. The vulnerability is not listed in CISA's KEV catalog. Exploitation requires a user to already possess delegated administrator privileges for organization management, so the attack vector is internal and limited to environments where such authorities exist. If an attacker can retrieve the invitation link, they can elevate their own account privileges within that organization, enabling further unwanted actions.

Generated by OpenCVE AI on August 1, 2026 at 08:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑published security patch for all affected Red Keycloak (e.g., Red Hat Build of Keycloak, Red Hat Single Sign‑On 7, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform Expansion Pack).
  • Disable or restrict the ability of delegated administrators to retrieve invitation links from the API; configuration changes should limit this feature to users with explicit need.
  • Review delegated administrator assignments and reduce permissions for any users who do; consider enforcing least‑privilege access control.
  • Monitor API logs for unusual or unauthorized retrieval of organization invitation links and investigate any suspicious activity promptly.

Generated by OpenCVE AI on August 1, 2026 at 08:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat build Of Keycloak
Redhat data Grid
Redhat jboss Enterprise Application Platform Expansion Pack
Redhat single Sign On
Vendors & Products Redhat build Of Keycloak
Redhat data Grid
Redhat jboss Enterprise Application Platform Expansion Pack
Redhat single Sign On

Tue, 21 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sat, 18 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 17 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to manage organizations can create an invitation for a non-existent email address and then retrieve the secret registration link directly through the application programming interface. By using this link, the administrator can create new user accounts and add them to the organization without having the required user management permissions or access to the invited email account. This allows an administrator to bypass security boundaries and add unauthorized members to an organization.
Title Keycloak-services: keycloak-services: organization invitation link exposure allows unauthorized member creation
First Time appeared Redhat
Redhat build Keycloak
Redhat jboss Data Grid
Redhat jbosseapxp
Redhat red Hat Single Sign On
CPEs cpe:/a:redhat:build_keycloak:
cpe:/a:redhat:jboss_data_grid:8
cpe:/a:redhat:jbosseapxp
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat build Keycloak
Redhat jboss Data Grid
Redhat jbosseapxp
Redhat red Hat Single Sign On
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Redhat Build Keycloak Build Of Keycloak Data Grid Jboss Data Grid Jboss Enterprise Application Platform Expansion Pack Jbosseapxp Red Hat Single Sign On Single Sign On
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-07-21T16:52:16.803Z

Reserved: 2026-07-17T13:26:09.324Z

Link: CVE-2026-16072

cve-icon Vulnrichment

Updated: 2026-07-17T17:27:39.238Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-16T17:09:24Z

Links: CVE-2026-16072 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:36:06Z

Weaknesses